i think, first we have to create one profile with all the permission and rights. after creating user, then apply that profile to that user.
in my office, the IT guys always done it. they have few profiles in the server, they just created new user and apply the profile.
we can't disable the services, because it will go for all users. we have to go with profiles, when profile will get loaded, the services are disable automaticaly for that user.
i'm just sending my opinion. i'm not sure about that.